
108 MetaFrame Solutions Guide
machine that uses the domain controller to be authenticated using the SecurID
solution.
Any machine, whether local or domain, on which you want to use SecurID
authentication must have the ACE/Agent installed.
Two example configurations are shown below:
Example 1
An ICA Client, using RAS, connects to the MetaFrame server Server_1 in the
domain DC_EX and the user specified is a member of DC_EX’s domain
Sdremote user group. The user is challenged with the SecurID authentication.
In this example, both Server_1 and DC_EX must have the ACE/Agent
installed.
Example 2
An ICA Client, using ICA remote control, connects to the MetaFrame server
named Server_2 and logs into domain DC_EX2. The user is a member of
DC_EX2’s domain Sdlocal group. The user is challenged with the secondary
authentication.
Both Server_2 and DC_EX2 must have the ACE/Agent installed.
Troubleshooting
When I try to connect to the MetaFrame server using RAS, it drops the connection
whenever it tries to verify the username and password on the network.
Do not forget to turn on the terminal mode after dialin option on the RAS client
side. This option is essential or you will not be prompted by the SecurID
authentication.
When I try to log on to the MetaFrame
server using a RAS or session connection,
I get a “User access denied” message. The ACE/Server log shows the message
“Node verification failed.”
There are two possible causes. First, check to see if the client configuration on the
ACE/Server has the Sent Node Secret box checked. If it does, uncheck it. Next,
on the MetaFrame server, look in the %SystemRoot%\System32 directory. If the
file Securid exists, delete it. Try to log on again. If you still get the failure, delete
the Sdconf.rec file from the %SystemRoot%\System32 directory and obtain a
current copy from Security Dynamics.
Note
Note
Note
Kommentare zu diesen Handbüchern